Close Menu
NCIJ Network NCIJ Network
    What's Hot

    Cities Compete in Dizzying ‘Gold Rush’ to Be Japan’s Backup Capital

    August 22, 2026

    How the Billionaire Joe Lonsdale Shaped Trump’s Homelessness Policy

    August 22, 2026

    Anthropic’s Opus 4.6 is a smut-machine

    August 22, 2026
    Facebook X (Twitter) Instagram
    Trending
    • Cities Compete in Dizzying ‘Gold Rush’ to Be Japan’s Backup Capital
    • How the Billionaire Joe Lonsdale Shaped Trump’s Homelessness Policy
    • Anthropic’s Opus 4.6 is a smut-machine
    • Microsoft Patches Severe Entra ID Flaw (CVSS 10.0) Allowing Remote Code Execution
    • Pakistan’s Crypto Pitch: “Come Build Here”
    • Iran Shows No Military Can Do the Impossible
    • Lindsay Clancy suffering ‘command hallucination’ when she killed children, court hears
    • Why Polling Chaos Could Create Big Problems for American Politics
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Saturday, August 22
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    Cisco Patches Nine Crosswork and Secure Workload Flaws, Five Scoring CVSS 10.0

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKAugust 22, 2026 Cybersecurity No Comments3 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Ravie LakshmananAug 21, 2026Vulnerability / Enterprise Security

    Cisco has published another round of security updates for Crosswork platforms and Secure Workload Software as part of a continued comprehensive internal security review.

    Four of the security vulnerabilities affect Crosswork Data Gateway, Crosswork Network Controller, and Crosswork Planning, regardless of the device configuration. A brief description of each of the flaws is below –

    • CVE-2026-20030 (CVSS score: 10.0) – An SQL injection vulnerability
    • CVE-2026-20357 (CVSS score: 10.0) – A missing authentication for critical function vulnerability
    • CVE-2026-20358 (CVSS score: 10.0) – An external control of file system vulnerability
    • CVE-2026-20359 (CVSS score: 9.9) – An insufficiently protected credentials vulnerability

    The issues affect Cisco Crosswork Release version 7.2.1 and earlier, and have been addressed in version 7.2.1-SP.

    Cybersecurity

    Cisco has also released fixes to remediate five vulnerabilities affecting Cisco Secure Workload, including Software-as-a-Service (SaaS) and on-premises deployments –

    • CVE-2026-20231 (CVSS score: 9.9) – A set of improper neutralization of special elements vulnerabilities spanning command, operating system, and argument injection
    • CVE-2026-20315 (CVSS score: 10.0) – A set of improper access control vulnerabilities spanning authorization, authentication, privileges, and bypasses
    • CVE-2026-20317 (CVSS score: 10.0) – A set of improper authentication vulnerabilities spanning missing authentication, authentication bypass, and reliance on untrusted inputs
    • CVE-2026-20318 (CVSS score: 9.6) – A set of improper input validation vulnerabilities spanning input validation, path traversal, and external path control
    • CVE-2026-20319 (CVSS score: 7.5) – A set of improper restriction of operations within the bounds of a memory buffer vulnerabilities spanning buffer overflows and out-of-bounds writes

    The five vulnerabilities have been patched in the versions below –

    • Cisco Secure Workload Release version 3.10 and earlier – Fixed in 3.10.9.1
    • Cisco Secure Workload Release version 4.0 – Fixed in 4.0.4.16

    “These vulnerabilities were found during internal testing and are not known to be actively exploited,” the company said, urging customers to apply the necessary updates to avoid future exposure.

    The development comes about two weeks after Cisco resolved 12 bugs impacting Catalyst SD-WAN and IOS XE Software following the internal security review. The review, the networking equipment major added, has “resulted in software hardening releases that address multiple internally discovered vulnerabilities.”

    The prevalence of Cisco gear within enterprise networks makes it an attractive target for bad actors, who have repeatedly exploited dozens of flaws impacting its products to gain unauthorized access and deploy malware.

    Earlier this month, Cisco warned that a vulnerability impacting Secure Firewall Adaptive Security Appliance (ASA) Software and Secure Firewall Threat Defense (FTD) Software (CVE-2026-20349, CVSS score: 8.6) has been exploited in the wild.

    Cisco Crosswork CVSS flaws Patches Scoring secure Workload
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    Microsoft Patches Severe Entra ID Flaw (CVSS 10.0) Allowing Remote Code Execution

    CISA Urges Immediate Patching of Exploited TrueConf Vulnerabilities

    Banking Trojans Manic, Grandoreiro, ToxicPanda 2.0 in the Spotlight

    Wazuh and AI For Enhanced SOC Workflows

    Contractors’ CMMC Confidence Rises as Ability to Prove It Falls Behind

    New Phishing Toolkit Uses Passkeys to Maintain Access After Password Resets

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    Cities Compete in Dizzying ‘Gold Rush’ to Be Japan’s Backup Capital

    August 22, 2026

    How the Billionaire Joe Lonsdale Shaped Trump’s Homelessness Policy

    August 22, 2026

    Anthropic’s Opus 4.6 is a smut-machine

    August 22, 2026

    Microsoft Patches Severe Entra ID Flaw (CVSS 10.0) Allowing Remote Code Execution

    August 22, 2026
    Latest Posts

    Satirical fake Guardian front page on ‘genetic links’ between eating bacon and far-right activism shared as genuine – Full Fact

    July 28, 2026

    U.S. Foreign Policy Must Prioritize Human Rights

    July 28, 2026

    Madison revisits police body cameras after years of debate

    July 28, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    Cities Compete in Dizzying ‘Gold Rush’ to Be Japan’s Backup Capital

    August 22, 2026

    How the Billionaire Joe Lonsdale Shaped Trump’s Homelessness Policy

    August 22, 2026

    Anthropic’s Opus 4.6 is a smut-machine

    August 22, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.